specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: CHAOSS providerId: chaoss generated: '2026-09-05' modified: '2026-09-05' method: searched source: >- https://github.com/chaoss/CollectOSS/blob/main/SECURITY.md and https://github.com/chaoss/grimoirelab/blob/main/SECURITY.md, both fetched 2026-09-05 (HTTP 200 via raw.githubusercontent.com). description: >- CHAOSS publishes a coordinated vulnerability disclosure policy per software project, not at the organization level. Both actively maintained CHAOSS products — CollectOSS and GrimoireLab — carry a SECURITY.md that forbids public issue reporting and routes reporters to GitHub private security advisories. present: true channel: github-security-advisory well_known_security_txt: false bug_bounty: false programs: - product: CollectOSS policy_url: https://github.com/chaoss/CollectOSS/blob/main/SECURITY.md report_url: https://github.com/chaoss/collectoss/security/advisories/new method: GitHub private vulnerability report public_reporting_prohibited: true supported_versions: >- Security updates are provided for the latest tagged release only. Older versions are not actively supported; maintainers may backport fixes case by case. responder: CollectOSS Security Response Committee (the CollectOSS maintainers) commitments: - Credit the reporter in security release notes unless anonymity is preferred - Coordinate disclosure and release timeline with the reporter - Keep the reporter's ticket updated with status embargo_window: null embargo_note: >- The policy commits to coordinating a timeline "based on our capacity to resolve the issue" and states no fixed number of days. No window is asserted here because none is published. - product: GrimoireLab policy_url: https://github.com/chaoss/grimoirelab/blob/main/SECURITY.md report_url: https://github.com/chaoss/grimoirelab/security/advisories/new method: GitHub private vulnerability report public_reporting_prohibited: true responder: GrimoireLab maintainers requested_details: - Detailed description of the vulnerability - Steps required to reproduce - Any suggested fixes or mitigations embargo_window: null gaps: - >- No /.well-known/security.txt is served on any CHAOSS host (35 paths probed across 5 hosts, all 404 — see well-known/chaoss-well-known.yml). An agent or scanner that looks only at the well-known path will conclude CHAOSS has no disclosure policy, which is wrong. - >- No organization-level SECURITY.md exists at github.com/chaoss/.github (HTTP 404, 2026-09-05), so repositories without their own SECURITY.md inherit nothing. maintainers: - FN: Kin Lane email: info@apievangelist.com